Executive Summary
In June 2026, Nissan disclosed a data breach affecting current and former employees across the United States, Canada, Mexico, and Brazil. The breach occurred between May 27 and June 9, 2026, when threat actors exploited a zero-day vulnerability (CVE-2026-35273) in Oracle's PeopleSoft software, which Nissan uses to manage employee information. The attackers, identified as the ShinyHunters extortion group, accessed sensitive personal data, including contact details, banking information, Social Security numbers, and tax information. Nissan promptly activated its incident response plan, engaged external cybersecurity experts, secured affected systems, and is collaborating with Oracle to address the issue. The company is offering free credit and dark web monitoring services to affected individuals and has implemented additional security measures to prevent further unauthorized access.
This incident underscores the critical importance of promptly addressing software vulnerabilities and implementing robust security measures to protect sensitive employee data. The exploitation of a zero-day vulnerability by a known threat actor highlights the evolving tactics of cybercriminals and the necessity for organizations to remain vigilant and proactive in their cybersecurity efforts.
Why This Matters Now
The Nissan data breach highlights the urgent need for organizations to address software vulnerabilities promptly and implement robust security measures to protect sensitive employee data. The exploitation of a zero-day vulnerability by a known threat actor underscores the evolving tactics of cybercriminals and the necessity for organizations to remain vigilant and proactive in their cybersecurity efforts.
Attack Path Analysis
Attackers exploited an unauthenticated remote code execution vulnerability in Oracle PeopleSoft PeopleTools to gain initial access. They then escalated privileges within the PeopleSoft environment, moved laterally to access sensitive employee data, established command and control channels, exfiltrated the data, and impacted Nissan by compromising employee personal and financial information.
Kill Chain Progression
Initial Compromise
Description
Exploitation of CVE-2026-35273 in Oracle PeopleSoft PeopleTools allowed unauthenticated remote code execution.
Related CVEs
CVE-2026-35273
CVSS 9.8A vulnerability in Oracle PeopleSoft Enterprise PeopleTools allows unauthenticated attackers to compromise the system via HTTP, potentially leading to full system takeover.
Affected Products:
Oracle Corporation PeopleSoft Enterprise PeopleTools – 8.61, 8.62
Exploit Status:
exploited in the wild
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Valid Accounts
Command and Scripting Interpreter
OS Credential Dumping
Exfiltration Over C2 Channel
Data Encrypted for Impact
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Ensure all system components are protected from known vulnerabilities
Control ID: 6.2
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Framework
Control ID: Article 5
CISA ZTMM 2.0 – Asset Management
Control ID: 3.1
NIS2 Directive – Cybersecurity Risk Management Measures
Control ID: Article 21
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Automotive
Nissan's Oracle PeopleSoft breach exposes critical vulnerabilities in automotive HR systems, requiring enhanced egress security and zero-day protection measures.
Higher Education/Acadamia
ShinyHunters primarily targeted education sector via CVE-2026-35273, compromising PeopleSoft instances and necessitating immediate segmentation and threat detection capabilities.
Computer Software/Engineering
Oracle zero-day exploitation demonstrates software sector's exposure to supply chain attacks, demanding robust vulnerability management and encrypted traffic protection.
Financial Services
Employee banking information theft creates regulatory compliance risks under NIST frameworks, requiring enhanced data loss prevention and anomaly detection systems.
Sources
- Nissan discloses employee data breach linked to Oracle zero-day attackshttps://www.bleepingcomputer.com/news/security/nissan-discloses-employee-data-breach-linked-to-oracle-zero-day-attacks/Verified
- Oracle Security Alert for CVE-2026-35273https://www.oracle.com/security-alerts/alert-cve-2026-35273.htmlVerified
- CISA Known Exploited Vulnerabilities Catalog Entry for CVE-2026-35273https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-35273Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Implementing Aviatrix Zero Trust CNSF would likely have constrained the attacker's ability to move laterally and exfiltrate sensitive data by enforcing strict segmentation and identity-based access controls.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: The attacker's initial access may have been limited to the compromised workload, reducing the potential for further exploitation.
Control: Zero Trust Segmentation
Mitigation: The attacker's ability to escalate privileges may have been constrained, reducing their access to sensitive systems.
Control: East-West Traffic Security
Mitigation: The attacker's lateral movement could have been restricted, limiting access to sensitive data.
Control: Multicloud Visibility & Control
Mitigation: The attacker's ability to establish command and control channels may have been detected and disrupted.
Control: Egress Security & Policy Enforcement
Mitigation: The attacker's data exfiltration efforts could have been detected and blocked.
The overall impact of the breach may have been significantly reduced, limiting exposure of sensitive employee information.
Impact at a Glance
Affected Business Functions
- Human Resources Management
- Payroll Processing
- Tax Administration
- Employee Records Management
Estimated downtime: N/A
Estimated loss: N/A
Personal information of current and former employees, including contact details, banking information, Social Security numbers, Social Insurance Numbers, National Identification Numbers, financial and tax information, and dependent and beneficiary information.
Recommended Actions
Key Takeaways & Next Steps
- • Implement inline Intrusion Prevention Systems (IPS) to detect and block exploitation attempts of known vulnerabilities like CVE-2026-35273.
- • Enforce Zero Trust Segmentation to limit lateral movement within the network, restricting access to sensitive data.
- • Utilize East-West Traffic Security controls to monitor and control internal traffic, detecting unauthorized access attempts.
- • Deploy Egress Security & Policy Enforcement mechanisms to prevent unauthorized data exfiltration.
- • Enhance Threat Detection & Anomaly Response capabilities to identify and respond to suspicious activities promptly.



